Regulation S-P: Safeguards, Incident Response, and the Notification Clocks

In plain language

Regulation S-P says you have to protect customer information, know when it has been exposed, and tell people about it on a clock. The 2024 amendments turned the last part into a written program with deadlines: customers get notified within 30 days of you becoming aware, and your vendors have to tell you within 72 hours of becoming aware. Almost all of the work is knowing where customer information actually lives before anything goes wrong.

What Regulation S-P actually requires

Regulation S-P (17 CFR Part 248) has three operating parts that a technology program has to answer for.

Privacy notices and opt-out. The firm tells customers what it does with nonpublic personal information and gives them a way to limit some sharing. This part is mostly a disclosure exercise, but it constrains technology in one important way: if the notice says information is not shared with a category of third party, the systems have to actually behave that way.

The Safeguards Rule. 17 CFR 248.30(a) requires written policies and procedures containing administrative, technical, and physical safeguards reasonably designed to protect customer records and information. “Reasonably designed” is the whole game. There is no control list to check off, which means the defensible position is a documented decision about each risk rather than a product purchase.

The Disposal Rule. 17 CFR 248.30(b) requires reasonable measures to protect against unauthorized access in connection with the disposal of consumer report information. In practice this is about hardware and media leaving the building, and about what a cloud tenant does with deleted data.

What the 2024 amendments added

The SEC adopted amendments to Regulation S-P in May 2024 (Release 34-100155, press release). They apply to broker-dealers, investment companies, SEC-registered investment advisers, funding portals, and registered transfer agents. Three things changed materially.

A written incident response program is now required

The safeguards policies must include a written incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. It has to include procedures for assessing the nature and scope of an incident, containing and controlling it, and notifying affected individuals.

The word doing the work is written. Many firms already had an escalation habit — a call tree, an MSP on retainer, an understanding that the CCO gets told. None of that is an incident response program until the assessment and notification procedures exist on paper and someone has approved them.

Customers get notified within 30 days

Notice must be provided as soon as practicable, and no later than 30 days after the firm becomes aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. The notice describes the incident, the information involved, and what the affected person can do.

Thirty days is an outer bound, not a target, and it starts at awareness rather than at confirmation. That has a practical consequence for logging: if you cannot determine whose information was reached, you cannot narrow the notification population, and the safe answer becomes the broad one. Log retention is therefore a notification-cost control, not just a security control.

Service providers get 72 hours

The firm must have written policies and procedures reasonably designed to require its service providers to take appropriate measures to protect against unauthorized access to customer information, including notifying the firm as soon as possible and no later than 72 hours after becoming aware of a breach in a system maintaining customer information.

The rule binds the firm, so the mechanism is contractual. A service provider that has not agreed to the 72-hour clause is not going to discover the obligation on its own. See vendor and service-provider oversight for how to run the register that makes this auditable.

Compliance dates

The amendments give larger covered institutions 18 months and smaller covered institutions 24 months from Federal Register publication. Measured from the June 3, 2024 publication date, that is December 3, 2025 for larger covered institutions and June 3, 2026 for smaller ones. Firm-size definitions are in the release; they are not the same thresholds used elsewhere in the Advisers Act rules, so read them rather than assuming.

Where firms usually find the gap

The pattern is consistent, and it is rarely the firewall.

  • Customer information in places nobody inventoried. Exported spreadsheets, a years-old file share, the CRM’s attachment store, an advisor’s personal archive of client statements, a marketing tool that received a client list once.
  • Logs that expire before they are needed. A 30-day retention default means an incident discovered in week six cannot be scoped.
  • Vendor agreements that predate the clause. The 72-hour obligation is missing from every contract signed before the firm started asking for it, which is usually most of them.
  • An incident response program that does not name the notification decision-maker. The containment steps are written and the disclosure step says “notify as required.”

How this connects to the rest of the program

The Safeguards Rule is the substantive obligation, and Advisers Act Rule 206(4)-7 is the rule that requires you to have policies and review them. For advisers, a Regulation S-P failure usually shows up as a 206(4)-7 finding as well. Broker-dealers should read this alongside FINRA supervision and cybersecurity.

The incident response half of this section is developed further in incident response and exam evidence, and the access side in access control and MFA.

Pylon’s service pages cover the same ground from the delivery side: Regulation S-P compliance and RIA cybersecurity.

Primary sources

Frequently Asked Questions

When does the 30-day Regulation S-P notification clock start?

It starts when the firm becomes aware that unauthorized access to, or use of, customer information has occurred or is reasonably likely to have occurred. Notice must go out as soon as practicable and no later than 30 days after that point. The clock is not tied to when the incident happened or when the investigation finished.

Does Regulation S-P apply to registered investment advisers, or only broker-dealers?

Both. The amended rule applies to broker-dealers, investment companies, SEC-registered investment advisers, funding portals, and transfer agents registered with the Commission. The compliance dates differ by firm size, not by registration type.

What is the difference between Regulation S-P and Regulation S-ID?

Regulation S-P is about safeguarding and disposing of customer information and notifying people when it is exposed. Regulation S-ID is about detecting and responding to the misuse of that information to commit identity theft. The same systems tend to produce evidence for both, which is why firms often run one program with two reporting views.

Does a service provider have to notify us in 72 hours, or do we have to put that in the contract?

Practically, the contract is how it happens. The rule requires the covered institution to have written policies and procedures reasonably designed to require service providers to provide notification as soon as possible and no later than 72 hours after becoming aware of a breach. If the agreement is silent, the obligation is not operative for that vendor and the firm has a gap to close.

Scheduled actions

The recurring work this section implies. Each action carries a stable action-id so it can be tracked in a compliance calendar and rolled up on all scheduled actions.

Re-verify the inventory of systems and vendors that store, process, or can reach customer information, including anything added by a new tool, integration, or acquisition.

Cadence:
Quarterly
Owner archetype:
CCO, MSP
action-id:
act.reg-s-p.customer-info-inventory-review

Review and re-approve the written incident response program, including the assessment, containment, and notification procedures, and record who approved it.

Cadence:
Annually
Owner archetype:
CCO
action-id:
act.reg-s-p.ir-program-review

Run a tabletop that exercises the customer notification decision specifically: who determines scope, who drafts the notice, who approves it, and how the 30-day clock is documented.

Cadence:
Annually
Owner archetype:
CCO, MSP
action-id:
act.reg-s-p.notification-tabletop

Confirm every service provider with access to customer information is under an agreement carrying the 72-hour breach notification obligation, and log the exceptions that are still open.

Cadence:
Annually
Owner archetype:
CCO, IT
action-id:
act.reg-s-p.service-provider-clause-audit

Verify that decommissioned media, retired endpoints, and expired records containing consumer report information were disposed of under the Disposal Rule, and keep the certificates.

Cadence:
Quarterly
Owner archetype:
IT, MSP
action-id:
act.reg-s-p.disposal-verification

Before a new system goes live, determine whether it will hold customer information and, if it will, add it to the inventory and bring it under the safeguards and notification program.

Cadence:
On change
Owner archetype:
IT, MSP
action-id:
act.reg-s-p.new-system-scope-check

Configuration touchpoints

Where this section lands in a real environment. Each touchpoint is stated as a plain configuration rule — not a vendor setting — and carries a stable config-id.

Configuration ruleApplies toconfig-id
Every system, share, mailbox, and vendor that can reach customer information appears in one inventory with a named owner and a recorded last-review date.Asset and data inventorycfg.reg-s-p.customer-info-inventory
Customer information is encrypted where it is stored and whenever it moves outside the firm's network, including email containing account numbers.Endpoints, file storage, email gatewaycfg.reg-s-p.encryption-at-rest-and-in-transit
Access to systems holding customer information is logged, and those logs are retained long enough to reconstruct who saw what during an incident investigation.Identity provider, file storage, line-of-business applicationscfg.reg-s-p.access-logging-retained
Alerts that would indicate unauthorized access to customer information route to a monitored queue with a defined response time, not to an individual's inbox.SOC / monitoring platformcfg.reg-s-p.breach-detection-alerting
For each in-scope service provider, the firm records the channel a 72-hour breach notice would arrive on and who monitors it outside business hours.Vendor registercfg.reg-s-p.vendor-notification-contact
Media and devices that held customer information are wiped or destroyed to a documented standard before leaving the firm's control.Endpoint lifecycle, decommissioning processcfg.reg-s-p.secure-disposal

More in the Compliance Library

Rollups: all scheduled actions and monitor and review.

Author
Rachel Lannon and Byron Foley
Reviewed by
Tim Quinn
Last updated

This is operational technology guidance for regulated firms, not legal advice. Confirm how each requirement applies to your firm with your compliance counsel.